Information Systems Security Management: A Review and a Classification of the ISO Standards

被引:0
|
作者
Tsohou, Aggeliki [1 ]
Kokolakis, Spyros [1 ]
Lambrinoudakis, Costas [1 ]
Gritzalis, Stefanos [1 ]
机构
[1] Univ Aegean, Dept Informat & Commun Syst Engn, GR-83200 Samos, Greece
关键词
Information security management systems; standardization;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The need for common understanding and agreement of functional and non-functional requirements is well known and understood by information system designers. This is necessary for both: designing the "correct" system and achieving interoperability with other systems. Security is maybe the best example of this need. If the understanding of the security requirements is not the same for all involved parties and the security mechanisms that will be implemented do not comply with some globally accepted rules and practices, then the system that will be designed will not necessarily achieve the desired security level and it will be very difficult to securely interoperate with other systems. It is therefore clear that the role and contribution of international standards to the design and implementation of security mechanisms is dominant. In this paper we provide a state of the art review on information security management standards published by the International Organization for Standardization and the International Electrotechnical Commission. Such an analysis is meaningful to security practitioners for an efficient management of information security. Moreover, the classification of the standards in the clauses of ISO/IEC 27001:2005 that results from our analysis is expected to provide assistance in dealing with the plethora of security standards.
引用
收藏
页码:220 / +
页数:5
相关论文
共 50 条
  • [1] A Systematic Management Method of ISO Information Security Standards for Information Security Engineering Environments
    Suhaimi, Ahmad Iqbal Hakim
    Manji, Takashi
    Goto, Yuichi
    Cheng, Jingde
    [J]. INFORMATICS ENGINEERING AND INFORMATION SCIENCE, PT I, 2011, 251 : 370 - 384
  • [2] Information security management system standards
    Edward Humphreys
    [J]. Datenschutz und Datensicherheit - DuD, 2011, 35 (1) : 7 - 11
  • [3] COMPARATIVE STUDY REGARDING INTERNATIONAL STANDARDS ON INFORMATION SECURITY MANAGEMENT SYSTEMS IN ORGANIZATIONS: ISO/IEC 27001:2013 vs ISO/IEC 27001:2005
    Tiganoaia, Bogdan
    [J]. GLOBALIZATION AND INTERCULTURAL DIALOGUE: MULTIDISCIPLINARY PERSPECTIVES - ECONOMY AND MANAGEMENT, 2014, : 102 - 109
  • [4] A REVIEW ON ENTERPRISE INFORMATION SECURITY AND STANDARDS
    Vural, Yilmaz
    Sagiroglu, Seref
    [J]. JOURNAL OF THE FACULTY OF ENGINEERING AND ARCHITECTURE OF GAZI UNIVERSITY, 2008, 23 (02): : 507 - 522
  • [5] Security standards for medical information systems
    Humphreys, T
    [J]. TOWARDS SECURITY IN MEDICAL TELEMATICS: LEGAL AND TECHNICAL ASPECTS, 1996, 27 : 131 - 144
  • [6] Information Security Management Systems - A Maturity Model Based on ISO/IEC 27001
    Proenca, Diogo
    Borbinha, Jose
    [J]. BUSINESS INFORMATION SYSTEMS (BIS 2018), 2018, 320 : 102 - 114
  • [7] Toward an Effective Information Security Risk Management of Universities' Information Systems Using Multi Agent Systems, Itil, Iso 27002, Iso 27005
    Faris, S.
    Medromi, H.
    El Hasnaoui, S.
    Iguer, H.
    Sayouti, A.
    [J]. INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2014, 5 (06) : 114 - 118
  • [8] Information security management standards: Problems and solutions
    Siponen, Mikko
    Willison, Robert
    [J]. INFORMATION & MANAGEMENT, 2009, 46 (05) : 267 - 270
  • [9] ISEDS: An information security engineering database system based on ISO standards
    Horie, Daisuke
    Morimoto, Shoichi
    Azimah, Noor
    Goto, Yuichi
    Cheng, Jingde
    [J]. ARES 2008: PROCEEDINGS OF THE THIRD INTERNATIONAL CONFERENCE ON AVAILABILITY, SECURITY AND RELIABILITY, 2008, : 1219 - +
  • [10] State of standards in the information systems security area
    Fernandez-Medina, Eduardo
    Yaguee, Mariemma I.
    [J]. COMPUTER STANDARDS & INTERFACES, 2008, 30 (06) : 339 - 340